Method and device for generating right object, method and device for transmitting right object, and method and device for receiving right object
Abstract
Method and device for generating Object with Rights (RO), method and device for transmitting Object with Rights, and method and device for receiving Object with Rights. Method for transmitting a (RO) on a device, in which a password key of a predetermined length is generated by creating encryption of a received password, where the (RO) is generated using the password key password, and where (RO) is transmitted to a second device.

Term
2.5 yearsleft in the term
Expires 25 March 2029.
- Priority
- Filed
- Granted
- Today
- Expires
32 claims: 6 independent, 26 dependent
- 1Claims Reivindicações 1. Method for the generation of an Object with Rights, said, in a simplified way, as a (RO), characterized by the fact of understanding:1. Método para a geração de um Objeto com Direitos, dito, de um modo simplificado, como um (RO), caracterizado pelo fato de compreender: - a geração de uma chave de senha com um comprimento pré-determinado pela criação de uma criptografia de uma senha recebida;e - the generation of a password key with a predetermined length by creating an encryption of a received password;and - a geração do (RO) usando a chave de senha. - the generation of (RO) using the password key.
- 6Device for the generation of an Object (RO) with Rights, characterized by the fact of understanding:6. Dispositivo para a geração de um Objeto (RO) com Direitos, caracterizado pelo fato de compreender: - a user input portion to receive a password key;and - uma porção de entrada de usuário para receber uma chave de senha;e - a controller for generating a password key of a predetermined length by creating an encryption of the received password and generating the (RO) using the password key. - um controlador para a geração de uma chave de senha de um pré-determinado comprimento pela criação de uma criptografia da senha recebida e a geração do (RO) usando a chave de senha.
- 11Method for the transmission of an Object (RO) with Rights in a device, characterized by the fact of understanding:11. Método para a transmissão de um Objeto (RO) com Direitos em um dispositivo, caracterizado pelo fato de compreender: - a geração de uma chave de senha com um comprimento pré-determinado pela criação de uma criptografia de uma senha recebida;- the generation of a password key with a predetermined length by creating an encryption of a received password;- a geração do (RO) usando a chave de senha;e - generating the (RO) using the password key;and - a transmissão do (RO) a um segundo dispositivo. - the transmission of the (RO) to a second device.
- 18Device for the generation of an Object (RO) with Rights, characterized by the fact of understanding:18. Dispositivo para a geração de um Objeto (RO) com Direitos, caracterizado pelo fato de compreender: - a user input portion to receive a password key;- uma porção de entrada de usuário para receber uma chave de senha;- a controller for generating a password key of a predetermined length by creating an encryption of the received password and generating the (RO) using the password key;and - um controlador para a geração de uma chave de senha de um pré-determinado comprimento pela criação de uma criptografia da senha recebida e a geração do (RO) usando a chave de senha;e - a communication module for transmitting the (RO) to a second device. - um módulo de comunicação para a transmissão do (RO) a um segundo dispositivo.
- 25Method for receiving an Object (RO) with Rights in a device, characterized by the fact of understanding:25. Método para a recepção de um Objeto (RO) com Direitos em um dispositivo, caracterizado pelo fato de compreender: - a recepção do (RO) de um segundo dispositivo;- receiving the (RO) from a second device;- a geração de uma chave de senha com um comprimento pré-determinado pela criação 5 de uma criptografia de uma senha compartilhada com o segundo dispositivo;e - the generation of a password key with a predetermined length by creating a password encryption 5 shared with the second device;and - a interpretação do (RO) usando a chave de senha. - interpretation of (RO) using the password key.
- 29Device for receiving an Object (RO) with Rights, characterized by the fact of understanding;29. Dispositivo para a recepção de um Objeto (RO) com Direitos, caracterizado pelo fato de compreender;- a communication module for receiving (RO) from a second device;- um módulo de comunicação para a recepção do (RO) de um segundo dispositivo;- a warehouse for storing a password shared with the second device;and - um armazém para o armazenamento de uma senha compartilhada com o segundo 25 dispositivo;e - - a controller for generating a password key of a predetermined length by creating a shared password encryption and interpreting the (RO) using the password key. - - um controlador para a geração de uma chave de senha de um pré-determinado comprimento pela criação de uma criptografia da senha compartilhada e a interpretação do (RO) usando a chave de senha.
Independent claims6
99 paragraphs, as filed
(54) Title: METHOD AND DEVICE FOR THE GENERATION OF OBJECT WITH RIGHTS (RO), METHOD AND DEVICE FOR THE TRANSMISSION OF OBJECT WITH RIGHTS, AND METHOD AND DEVICE FOR THE RECEIPT OF OBJECT WITH RIGHTS (30) Unionist Priority: 26/03 / 2008 kr 10-2008-0027891 (73) Holder (s): pantech & curitelCommunications, inc (72) Inventor (s): gun-wook kim (57) Summary: Method and device for generating Object with Rights (RO), method and device for transmitting Object with Rights, and method and device for receiving Object with Rights. Method for transmitting a (RO) on a device, in which a password key of a predetermined length is generated by creating encryption of a received password, where the (RO) is generated using the password key password, and where (RO) is transmitted to a second device.
<td>device</td><td></td><td>IR</td><td></td><td>OCSP response provider | .........</td>
<td> --</td><td colspan="3"></td><td></td>
<td></td><td>hello positive</td><td></td><td></td><td></td>
<td></td><td>IR of - Hello</td><td></td><td></td><td></td>
<td></td><td>T — requisition from register__ S3</td><td></td><td>S10 -_request</td><td></td>
<td></td><td>S4 Ç ~ answer - record</td><td></td><td>from OCSP response from OCSP S11</td><td>J</td>
1/9
ΡΙ0900533-1
Method and device for generating Object with Rights (RO), method and device for transmitting Object with Rights, and method and device for receiving Object with Rights
This application claims the priority and benefit of 5 Korean Patent Application N <sup>0</sup> 10-2008-0027891, completed on March 26,
2008, the exhibition of which is incorporated here in its entirety as a reference.
The description that follows refers to digital rights management technology and, more particularly, to a method and device for generating and transmitting an object with rights during digital rights management.
Digital Right Management (DRM, or “Digital Right
Management ”) is a technology that protects and manages the rights of copyright owners of digital content. The saying (DRM) involves technologies to create encryption, watermarks and duplication prevention.
* Digital copyright data is encoded in the DRM Content Format (DCF, or “DRM Content Format”) digital content using a Right Object (RO, or “Right Object”) including encoded digital content and access right information content before distribution. A Right Issuer (RI, or Right Issuer ”) creates the (RO) and provides it to a device that will use the content (DRM). Because digital copyright data is accessible only with a (RO) having a key with which to decrypt digital copyright data, a device that wants to receive digital content should acquire the (RO) as well as the content.
The description that follows refers to a method and device for generating a (RO) based on a password on a device.
The description that follows refers to a method and a device for the generation and transmission of an (RO) in a device.
The following description refers to a method and device for receiving a (RO) from a transmission device
According to one aspect as an example, there is the provision of a method for the generation of a (RO), in which a password key with a predetermined length is generated by creating an encryption of a received password, and the ( RO) is generated using the password key.
According to another aspect as an example, there is the provision of a device for the generation of a (RO), in which a user input portion receives a password key, and a controller generates a password key with a pre-defined length. determined by the creation of an encryption of the received password and generates the (RO) using the password key.
According to another aspect as an example, there is the
2/9 providing a method for transmitting a (RO) on a device, in which a password key of a predetermined length is generated by creating an encryption of a received password, the (RO) is generated using the password key, and the (RO) is transmitted to a second device.
According to yet another aspect as an example, there is the provision of a device for the generation of a (RO), in which a portion of user input receives a password key, a controller generates a password key with a predetermined length by creating an encryption of the received password, and generates the (RO) using the password key, and a communication module transmits the (RO) to a second device.
According to yet another aspect as an example, there is the provision of a method for receiving a (RO) on a device, in which the (RO) of a second device is received, a password key with a predetermined length is generated by creating a password encryption shared with the second device, and the (RO) is interpreted using the password key.
According to another aspect as an example, there is the provision of a device for the reception of a (RO), in which a communication module receives the (RO) of a second device, a warehouse stores a password shared with the second device , and a controller generates a password key with a predetermined length by creating a shared password encryption and interprets the (RO) using the password key.
Additional aspects of the invention will be demonstrated in the description that follows, and, in part, will be evident from the description, or can be grasped by the practice of the invention.
It should be understood that both the following generic description and the following detailed description are for an example and explanation and are intended to provide further explanation of the invention, as claimed.
The accompanying drawings, which are included to provide a better understanding of the invention, and which are incorporated herein, forming part of this specification, which together with the description serve to explain aspects of the invention, show configurations of examples of the invention, in which :
.- Figure 1 shows a 4 - step registration protocol of Open Mobile Alliance (OMA, or Open Mobile Allíance) - (DRM) v.2.0;
- Figure 2 shows a 2-step (RO) acquisition protocol (OMA DRM) v.2.0;
Figure 3 shows an operation of transmitting (RO) between devices according to an example configuration of the present invention;
3/9 Figure 4 shows a (RO) according to an example configuration of the present invention;
Figure 5 shows a device for generating and transmitting an (RO) or receiving an (RO) according to an example configuration of the present invention;
Figure 6 is a flow table showing a method for generating and transmitting an (RO) according to an example configuration of the present invention;
Figure 7 is a flow table showing a method for generating a (RO) according to an example configuration of the present invention;
Figure 8 is a flow table showing a method for receiving a (RO) according to an example configuration of the present invention;
Figure 9 is a flow table showing a method for interpreting a (RO) according to an example configuration of the present invention.
The invention is more fully described below with reference to the accompanying drawings, in which exemplary configurations of the invention are shown. This invention can, however, be configured in many different ways and should not be construed as limited to the example configurations demonstrated here. Preferably, these example configurations are provided so that this discovery is comprehensive, and will lead the scope of the invention to those skilled in the art. In the drawings, the size and relative sizes of the layers and regions can be exaggerated, for the sake of clarity. The similar reference numerals in the drawings denote similar elements.
(It should be understood that when an element or layer is referred to as “on” or “connected to” another element or layer, it can be directly connected or directly connected to the other element or layer, or elements or layers may be present In contrast, when an element is referred to as being "directly on" or "directly connected to" another element or layer, there is no intervention element or layer present.)
Fig. 1 shows a 4 - step registration protocol for Open Mobile Alliance (OMA, or "Open Mobile Alliance") - (DRM) v.2.0.
An (OMA DRM) v.2.0 requires a device to register with an (RI) through the 4-step registration protocol to acquire an (RO). The 4-step registration protocol is required to exchange and record information necessary for the device to communicate with (RI). If the 4-step registration protocol is successful, the device acquires a context of (RI) having information about the (RI) and the (RI) preserves the information about the device.
To be more specific, the above operation starts with the device transmitting a message from a Hello Device leading its
4/9 basic information to (Rl) in step S1. Upon receiving the message from the Hello Device, the (Rl) transmits a (Rl of Hello) message with the information (Rl) to the device in step S2. Upon receipt of the (Rl of Hello) message, the device transmits a Registration Request message to (Rl), for registration to (Rl) in step S3.
In step S10, the (Rl) transmits an Online Certificate Status Protocol Request (OCSP) message to an answer provider (OCSP). The response provider (OCSP) responds to (Rl) with a Response message (OCSP) in step S11. The (Rl), which received the registration request, transmits a Registration Response message including the Response message (OCSP) to the device in step S4.
Fig. 2 shows a 2-pass (RO) acquisition protocol (OMA DRM) v.2.0.
The device that registered in (Rl) in the manner shown in fig. 1 acquires a (RO) as follows. First, the device transmits a Request for (RO) message to (Rl) in step S20 and the (Rl) forwards a Request for (OCSP) message to the response provider for (OCSP) in step S30. In step S31, the response provider (OCSP) responds to (R1) with a Response message (OCSP). The (Rl), which received the Request for (RO) message, generates a (RO) and transmits it through a Response (RO) message to the device in step S21. The (RO) is encrypted with a device's public key to prevent other devices from using the (RO).
As described above, only (Rl) can generate a (RO) in accordance with (OMA DRM) v. 2. 0. The device can now generate the (RO) and transmit it to another device according to an example configuration of the present invention.
A device is an entity capable of using digital content according to an example configuration of the present invention. The device can be any one of several terminals that includes a mobile communication terminal, a digital TV, a Global Positioning System (GPS) browser, a portable game player, and a Layer 3 player from the Group of Image Experts in Motion (MP3, or “Moving Picture Experts Group Layer 3”).
Fig. 3 shows an operation of transmitting (RO) between devices according to an example configuration of the present invention.
According to the example configuration of the present invention, a device can generate a (RO) based on a user input password and transmit the (RO) to another device. The (RO) can be transmitted separately or together with the contents associated with the (RO) in one (DCF). Here, the (RO) transmission device is referred to as a first device (100) and the (RO) receiving device is referred to as a second device (200).
5/9
The first device (100) receives any user password in step S310 and generates a password key of a predetermined length using the password received in a predetermined method of creating encryption in step S320. For example, the first device (100) receives a password of a predetermined length and a desired key length and delivers a password key of the key length received by internal computing.
According to the example configuration of the present invention, while the password key can be generated in a password-based encryption creation method in accordance with Public Key Cryptography Standard (PKCS) # 5, any other method of creating encryption can be used as long as it guarantees security.
Then, the first device (100) generates a (RO) using the password key in step S330 and transmits (RO) to the second device (200) in step S340. The (RO) can be transmitted in such a method as the Infrared Data Association (IrDA, or “Infrared Data Association”), Multimedia Messaging System (MMS, or “Multimedia Messaging System), or Connect- e-Toque Universal (UPnP, or “Universal Plug & Play”), to which the present invention is not limited.
In step S350, the second device (200) interprets the (RO) and decodes a Content Encryption Key (CEK, or “Content Encryptíon Key'j, included in the (RO). According to the example configuration of the present invention , the second device (200) can share the password entry with the first device (100) and generates the password key by creating a password encryption in the same encryption creation method as that used on the first device (100). The second device (200) can interpret the (RO) with the password key.
In step S360, the second device (200) can recover the content by decoding the content using the decoded (CEK). Content can be received along with (RO) from the first device (100) or content that has been stored on the second device (200).
Fig. 4 shows a (RO) according to an example configuration of the present invention.
According to the example configuration, (RO) can include an element (RO) (410) with content of (RO) and an element (mac) (420) with information for verifying the integrity of the element (RO) ( 410). The (RO) can be generated in the Extensible Markup Language (XML, or “eXtensible Markup Language).
With reference to fig.4, the element (RO) (410) can include an Identifier (ID) field (412) having a device (ID), a first encryption creation key field (414) having a (CEK) (E (CEK)) encrypted, one second
6/9 encryption creation key field (416) having an encrypted MAC key and a Right Encryption Key (REK, or “Encryption Key”) (E (MAC, REK) encrypted, and another field (418 ) of information having other information.
(RO) is encrypted with (REK) being a symmetric key. Thus, a user can purchase (CEK) and access digital content, only if he or she has (REK).
The element (mac) (420) can include a signature value of the element (RO) (410) marked with the MAC key inserted in the second field (416) of the encryption creation key.
Fig. 5 shows a device for generating and transmitting an (RO) or receiving an (RO) according to an example configuration of the present invention.
According to the example configuration of the present invention, a device (500) includes a user input portion (510), a controller (520), a communication module (530), and a warehouse (540).
The user input portion (510) can be configured to be a user interface device for receiving various pieces of information including a user password. The controller (520) provides global control of the operations of the device (500), including input / output of data between the components of the device (500). The communication module (530) can include an interface for communication with an external device, such as a wired / wireless communication interface with Internet, Bluetooth, Universal Serial Bus (USB), or an IrDA communication interface The warehouse (540) can store programs required for the operations of the device (500) or various pieces of information including multimedia content.
An operation of the device (500) in the case where it is a first device that cools and transmits an (RO) will be described first below.
Upon receipt of any user password, the device (500) can generate a password key with a length determined by creating a password encryption and generates an (RO) using the password key. A method of creating a password-based encryption for (PKCS) # 5 can be used for password key generation.
The controller (520) can generate a (REK) to create an encryption of a (CEK) and a MAC key to verify the integrity of the (RO). Also, controller (520) can create (CEK) encryption using (REK) and create (REK) and MAC key encryption using the password key.
For content associated with a (RO) received from a (RI), the (CEK) can be a (CEK) included in the (RO). On the other hand, if the
7/9 (RO) transmission manages the content, it can also generate the (CEK) for the creation of a content encryption.
The controller (520) can generate an (RO) using the encrypted (CEK) (E (CEK)) and the encrypted MAC key and (REK) (E (MAC, REK)). Specifically, the controller (520) can generate an (RO) that includes an element (RO) with a field (ID) having a device (ID) inserted, a first encryption creation key field having a (CEK) (E (CEK)) encrypted, and a second encryption creation key field having an encrypted MAC key and an encrypted (REK) (E (MAC, REK)), and an element (mac) that is signaled with the MAC key.
The controller (520) controls the communication module (530) to transmit the (RO) to another device which can share the user input password.
A description of an operation of the device (500) will now be made when the device (500) is a second device for receiving an (RO).
The (RO) receiving device (500) stores a password shared with another device that transmits an (RO) in the warehouse (540).
Upon receiving the (RO) from another device in the communication module (530), the controller (520) generates a password key with a predetermined length by creating a stored password encryption and interprets the (RO) using the password key.
The controller (520) decrypts an encrypted MAC key and an encrypted (REK) (E (MAC, REK)) included in the (RO). The controller (520) decodes an encrypted (CEK) (E (CEK)) included in the (RO) using the decoded (REK). Furthermore, the controller (520) can verify the integrity of the (RO) by checking a signature value included in the (mac) element of the (RO) using the MAC key.
The controller (520) can also retrieve content by decoding then using the decoded (CEK). The retrieved content can be sent via an output device (not shown) such as a speaker or a display.
Fig. 6 is a flow table showing a method for generating and transmitting an (RO) according to an example configuration of the present invention.
To generate and transmit an (RO), a device generates a password key by creating a password encryption received in step S610 and creates an (RO) using the password key in step S620. According to the example configuration of the present invention, (RO) can be generated in the procedure shown in fig.
8/9
7.
Fig. 7 is a flow table showing a method for generating an (RO) according to an example configuration of the present invention.
The device generates a (REK) to create an encryption of a (CEK) and a MAC key to certify the integrity of the (RO) in step S622. In step S624, the device creates (CEK) encryption using (REK).
For content associated with a (RO) received from an (RI), the (CEK) can be a (CEK) included in the (RO) received in step S624. On the other hand, if the (RO) transmission device manages the content, the S620 (RO) generation step may involve the (CEK) generation. Here, the device can generate the (CEK).
In step S626, the device creates the (REK) encryption and the MAC key encryption using the password key. The device can generate the (RO) using, in step S628, the encrypted (CEK) (E (CEK)) and the encrypted (REK) and MAC key (E (MAC, REK)).
With reference to fig. 6, again, the device transmits the (RO) to another device in step S630. The password can be shared between the (RO) transmitting device and the (RO) receiving device.
Fig. 8 is a flow table showing a method for receiving a (RO) according to an example configuration of the present invention.
A device receives an (RO) from another device in step S810 and generates a password key of a predetermined length by creating an encryption of a password shared with the (RO) transmitting device in step S820. In step S830, the device interprets the (RO) using the password key.
The interpretation of (RO) can be conducted according to the procedure shown in fig. 9.
Fig. 9 is a flow table showing a method for interpreting an (RO) according to an example configuration of the present invention.
The device decrypts the encrypted MAC key and (REK) (E (MAC, REK)) included in (RO) using the password key in step S832 and decrypts the encrypted (CEK) (E (CEK)) included in (RO) using the (REK) decoded in step S834. In step S836, the device checks the integrity of the (RO) using the decrypted MAC key.
The device can also decode the content using the (CEK) decoded in step S834.
As is evident from the description above, according to
9/9 In an example configuration of the present invention, a device can generate and transmit an (RO) to another device. Therefore, for content from an received (RI), a device that is made available to generate and transmit an (RO) can transmit the (RO) to another device by sharing a password so that the receiving device can receive the content from a transmission device without direct communication with (RI).
For content generated by the device, the device can transmit the content to another device by sharing a password without registering the content on a content management server, so that the receiving device can access the content. Therefore, content can be freely transmitted and received between devices that share a password, with guaranteed security for the content.
The aforementioned method according to the present invention can be stored on any form of recording media, such as a CD-ROM, RAM, ROM, floppy disk, hard disk, or optical-magnetic disk or in any computer readable form, such as organized computer code in executable programs. A description of a method of storing an example configuration of the present invention is well known in the art and will be omitted.
It will be apparent to those experienced in the field that various modifications and variations can be made to the present invention without departing from the spirit or scope of the invention. Therefore, it is intended that the present invention cover the modifications and variations of this invention provided that fall within the scope of the appended claims and their equivalents.
1/5
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
14 members in 7 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 20080027891 | Republic of Korea | A |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| CN101547101A | China | A | |
| EP2105857A2 | European Patent Office (EPO) | A2 | |
| KR20090102440A | Republic of Korea | A | |
| US2009249072A1 | United States of America | A1 | |
| JP2009238212A | Japan | A | |
| BRPI0900533A2This record | Brazil | A2 | |
| TW201003454A | Taiwan Province of China | A | |
| KR100973576B1 | Republic of Korea | B1 | |
| JP4945717B2 | Japan | B2 | |
| US8327145B2 | United States of America | B2 | |
| US2013067230A1 | United States of America | A1 | |
| CN101547101B | China | B | |
| EP2105857A3 | European Patent Office (EPO) | A3 | |
| US8699706B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapse as no evidence of payment of the annual fee has been furnished to inpi (acc. art. 87)LapsedB08K | B08K | |
| Application fees: dismissal - article 86 of industrial property lawB08F | B08F | |
| Publication of an application: publication of a patent application or of a certificate of addition of inventionB03A | B03A |
Numbers
- Application
- 9005331
Titles2
- Portuguese
- método e dispositivo para a geração de objeto com direitos (ro), método e dispositivo para a transmissão de objeto com direitos, e método e dispositivo para a recepção de objeto com direitos
- English
- method and device for generating object with rights (ro), method and device for transmitting object with rights, and method and device for receiving object with rights
Classification
- CPC, 2
- G06F21/10
- G06F21/00
- IPC, 6
- G06F21 62
- G06F21 64
- G06Q50 00
- G06Q50 10
- H04L9 12
- H04L9 32